Computer intrusion detection through EWMA for autocorrelated and uncorrelated data

Nong Ye, Sean Vilbert, Qiang Chen

Research output: Contribution to journalArticle

104 Scopus citations

Abstract

Reliability and quality of service from information systems has been threatened by cyber intrusions. To protect information systems from intrusions and thus assure reliability and quality of service, it is highly desirable to develop techniques that detect intrusions. Many intrusions manifest in anomalous changes in intensity of events occurring in information systems. In this study, we apply, test, and compare two EWMA techniques to detect anomalous changes in event intensity for intrusion detection: EWMA for autocorrelated data and EWMA for uncorrelated data. Different parameter settings and their effects on performance of these EWMA techniques are also investigated to provide guidelines for practical use of these techniques.

Original languageEnglish (US)
Pages (from-to)75-82
Number of pages8
JournalIEEE Transactions on Reliability
Volume52
Issue number1
DOIs
StatePublished - Mar 1 2003

Keywords

  • Anomaly detection
  • Computer audit data
  • Exponentially weighted moving average (EWMA)
  • Information assurance
  • Intrusion detection

ASJC Scopus subject areas

  • Safety, Risk, Reliability and Quality
  • Electrical and Electronic Engineering

Fingerprint Dive into the research topics of 'Computer intrusion detection through EWMA for autocorrelated and uncorrelated data'. Together they form a unique fingerprint.

  • Cite this